New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
C#: Add flow steps from a PageModel to cshtml page. #15039
base: main
Are you sure you want to change the base?
C#: Add flow steps from a PageModel to cshtml page. #15039
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I don't know enough about razor pages, but this looks plausible to me. I added one minor comment.
Let's wait for others to review it before merging.
| /** Gets a handler method such as `OnGetAsync` */ | ||
| Method getAHandlerMethod() { | ||
| result = this.getAMethod() and | ||
| result.getName().matches("On%") and |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Should OnPageHandler% methods be filtered out?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hmm, I guess those methods are not technically handler methods; however they are called during the page handler process, so it makes sense to consider tainted writes to the model in those methods to still propagate to the page.
|
|
||
| from DataFlow::Node source, DataFlow::Node sink | ||
| where TestXss::flow(source, sink) | ||
| select sink, source, sink, "Xss" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I suggest making this a path-problem query instead.
| private MethodCall getImplicitThisCallInVoidHandler(PageModelClass pm) { | ||
| result.getEnclosingCallable() = pm.getAHandlerMethod() and | ||
| result.getEnclosingCallable().getReturnType() instanceof VoidType and | ||
| result.hasImplicitThisQualifier() |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Why only implicit this qualifiers?
| PageModelClass pm; | ||
|
|
||
| PageModelJumpNode() { | ||
| this.asExpr() = [getAPageCall(pm), getImplicitThisCallInVoidHandler(pm)].getQualifier() |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
For the getImplicitThisCallInVoidHandler case, I would expect that the node should be the post-update node, as that is what is that target of stores. I.e., in this.Name = source() the store is into the post-update node for this.
Adds flow steps from
PageModelhandler methods (calls toPageModel.Page()andPageModel.RedirectToPage()as well as implicit flow fromthisin void-returning handler methods) to theModelfield in the code generated from the.cshtmlfile for the corresponding page.